SERVICE
Strategic consulting
Where your program stands today, measured against a recognized framework, and what moves the needle in the next twelve months, numbers, not impressions.
NIST CSF 2.012-month roadmapExecutive tabletop
AT A GLANCE
Frameworks NIST CSF 2.0 · ISO 27001 · SOC-CMM
Duration 2–6 weeks by tier
Includes Optional executive tabletop
Result Level per domain + roadmap
HOW WE WORK
The methodology, step by step
01
Baseline
Current state against NIST CSF 2.0, ISO 27001 and SOC-CMM.
02
Technical verification
Evidence and real configuration, not just what the interview says.
03
Agentic assessment
✦ AI AGENTThe tool reads policies and records and backs every level with the supporting document.
04
Level per domain
A score defensible before auditor, regulator and board.
05
12-month roadmap
What moves the needle, with associated investment and pending decision.
SERVICE TIERS
Pick the tier that answers your question
The price is fixed in writing after a 30-minute scoping and does not change during the contract.
Express
COVERS
6 key domains
DURATION
2 weeks
IDEAL FOR
A new CISO who needs the map
RESULT
Map and priorities
RECOMMENDED
Complete
COVERS
Full framework + technical verification
DURATION
4–6 weeks
IDEAL FOR
Annual budget or board requirement
RESULT
Level per domain + roadmap
Complete + re-assessment
COVERS
All + annual re-assessment
DURATION
4–6 weeks + follow-up
IDEAL FOR
Multi-year programs
RESULT
Improvement measured year on year
Thirty minutes and we tell you frankly what you need.
Sometimes the answer is "you don't need us yet." We prefer that to selling you something you won't use.